barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t
The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (St
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a
An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and
A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function
CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov
SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affe
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl
OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.
Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authentic
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorizat
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in
Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-cl
OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowin
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C
SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may par
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in
NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0
Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may
An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 al
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started